DevOps Hub/Cybersecurity
All systems operational
01 · AppSecLabs S1–S4

Application Security & Exploit Defense

Container & dependency scanners, OWASP Top 10 exploits, secrets management, and WAF hardening.

#sec-scanners · S1

1. SAST / DAST & Container Vulnerability Scanner

Simulate Trivy container image scans, Snyk SAST code analysis, and OWASP ZAP DAST web inspection. Identify CVEs, misconfigurations, and dependency risks before they reach production.

Scanner Controls

Select a scanner engine and target to begin vulnerability analysis.

Critical findings
2
Triage priority depends on context
High severity
3
Prioritize by exposure and exploitability
Medium severity
2
Review affected path and compensating controls
Low severity
1
Schedule according to risk

Detected findings (8)

Finding IDSeverityScannerComponentCVSS v3.1
CVE-2024-21626HIGHTrivyrunc8.6
CVE-2023-44487HIGHTrivynghttp2 / Envoy7.5
DEMO-SAST-001HIGHSnyk Codesrc/api/auth.ts:42—
CVE-2024-3094CRITICALTrivyxz / liblzma10.0
DEMO-DAST-001MEDIUMOWASP ZAPHTTPS response header—
DEMO-SAST-002MEDIUMSnyk Codelodash—
CVE-2023-38545CRITICALTrivylibcurl9.8
DEMO-DAST-002LOWOWASP ZAP/search?q=—

🔬 Finding Details & Fix

CVE-2024-21626 (Trivy)
Leaky Vessels container breakout in runc
Affected:
1.1.11
Remediated:
1.1.12

In runc 1.1.11 and earlier, a file-descriptor leak can give a container process access to the host filesystem in affected attack paths.

Upgrade runc or the vendor-provided container runtime to a patched release; verify the node and image supply chain.
#sec-owasp · S2

2. OWASP Top 10 Vulnerability Matrix & Remediation Lab

Select any OWASP Top 10:2025 category to inspect a display-only teaching scenario, compare vulnerable and remediated code, and identify the relevant defenses.

A01:2025

Broken Access Control

Impact: Data exposure, vertical or horizontal privilege escalation, and unauthorized API actions.

Failures allow unauthorized users to view, edit, or delete data belonging to other users (for example, IDOR and privilege escalation).

❌ Vulnerable ImplementationUNSECURE
// VULNERABLE: Trusting a user-supplied ID without authorization
app.get('/api/invoice/:id', authMiddleware, async (req, res) => {
  const invoice = await db.query('SELECT * FROM invoices WHERE id = $1', [req.params.id]);
  res.json(invoice); // No ownership or role check
});
✅ Remediated Secure ImplementationHARDENED
// REMEDIATED: Enforce authorization for the authenticated principal
app.get('/api/invoice/:id', authMiddleware, async (req, res) => {
  const invoice = await db.query(
    'SELECT * FROM invoices WHERE id = $1 AND owner_id = $2',
    [req.params.id, req.user.id]
  );
  if (!invoice) return res.status(404).json({ error: 'Not found' });
  res.json(invoice);
});
🛡️ Key Architectural Defenses:
  • •Enforce authorization at the domain/resource layer, not only in the UI
  • •Deny by default and test both horizontal and vertical access boundaries
  • •Log access-control failures without recording sensitive payloads
🧪 Display-only scenario tester
#sec-vault · S3

3. Secret Management Workflow (HashiCorp Vault vs AWS Secrets Manager)

Compare provider-specific secret storage, dynamic credential leases, access policy, and rotation workflows. The controls below are a local simulation.

🔐

HashiCorp Vault

MULTI-CLOUD / ON-PREM
  • •Key protection: Shamir shares can protect Vault unseal operations; the Transit engine is a separate encryption service.
  • •Dynamic secrets: A configured database role can issue short-lived credentials, such as a one-hour example lease.
  • •Authentication: AppRole, Kubernetes, TLS, and other methods are available depending on the enabled auth configuration.
☁️

AWS Secrets Manager

AWS NATIVE
  • •Encryption: Secrets Manager uses envelope encryption with a 256-bit AES data key protected by AWS KMS.
  • •Rotation: Managed rotation or a configured Lambda workflow updates both the secret and its target service.
  • •Access: IAM policies authorize API calls; a VPC endpoint can constrain the network path but is not an authentication method.

Secret Lifecycle Pipeline

Storage & key protection: Encryption details depend on the configured Vault seal/storage and AWS KMS settings. Shamir shares protect an unseal workflow; AWS Secrets Manager uses KMS envelope encryption.

💻 Secret Fetch & Rotation Simulator

Illustrative lease TTL: 3600s
#sec-waf · S4

4. Web Application Firewall (WAF) & TLS Hardening Lab

Configure illustrative request-filtering rules, compare TLS and HTTP-header settings, and inspect a local heuristic. A WAF is not a substitute for secure application code or dedicated DDoS protection.

WAF Rule Table (4 configured rules)

StateRule NameTypeActionBlocked Hits
OWASP Core Rule Set - SQL InjectionSQLiBLOCK1420
OWASP Core Rule Set - Cross Site Scripting (XSS)XSSBLOCK890
Rate Limit: Max 100 Reqs / 5 MinRateLimitBLOCK310
Geo-IP Filter: Block Tor Exit NodesGeoBlockCAPTCHA145
+ Add Custom WAF Rule:

📡 WAF Live Traffic Tester

TLS Hardening & Security Header Checklist

Configure a local teaching heuristic for TLS and response headers; this is not an SSL Labs grade.

Local grade:Grade A+
TLS Protocols & Ciphers:
HTTP Security Headers:
Audit Evaluation Result: Local heuristic: selected protocol and header examples are enabled.
02 · IdentityLabs S5–S8

Threat Modeling & Zero Trust Identity

STRIDE threat modeling, least-privilege IAM policies, BOLA/IDOR API security, and Zero Trust boundaries.

#sec-threat-model · S5

5. STRIDE Threat Modeling Canvas & Risk Matrix

Select an architecture asset, apply mitigations, and compare the remaining STRIDE findings against risk baselines.

Public request and application boundary

Applied mitigations

Web API findings

STRIDE threats ordered by severity.

Residual riskHigh
Risk score18 / 18
Open findings6
High or critical remaining5
Elevation of privilege
criticalOpen

A compromised endpoint may grant actions beyond the caller role.

Control: Least Privilege

Spoofing
highOpen

An attacker may impersonate a caller when identity checks are weak.

Control: Strong Authentication

Tampering
highOpen

Untrusted request data can alter application state.

Control: Input Validation

Information disclosure
highOpen

Overly broad responses can expose data to unauthorized callers.

Control: Object Authorization

Denial of service
highOpen

Unbounded requests can exhaust API capacity.

Control: Rate Limiting

Repudiation
mediumOpen

Without an audit trail, actions cannot be reliably attributed.

Control: Audit Logging

#sec-iam · S6

6. IAM, RBAC & Least Privilege Policy Engine

Build an access request and evaluate it against local role policies, wildcard rules, and MFA condition blocks.

Submit the request to see the evaluator decision, matched rule, and reason.

Local policy set

Deny rules are evaluated before matching Allow rules.

6 rules
IAM policy rules used by the evaluator
EffectPrincipalActionResourceCondition
Denyuser/*orders:Deleteorders/*—
Allowrole/api-readerorders:Getorders/*—
Allowrole/api-readerorders:Listorders/*—
Allowrole/ops-adminadmin:*admin/*MFA required
Allowservice/orders-workerorders:Updateorders/prod—
Allowrole/ops-adminorders:*orders/*MFA required
#sec-api-security · S7

7. Layered API Request & BOLA/IDOR Defense Lab

Test controls that protect an API boundary: identity, object ownership (BOLA), schema validation, and rate limits.

Read an order owned by the caller

Request controls

Evaluate the request to see the decision, matched concern, and recommended control.

Safe example request

This illustrative request is display-only. The lab never executes entered payload text or sends network traffic.

DISPLAY ONLY
GET /v1/orders/order_2048
Authorization: Bearer <short-lived-token>
IdentityVerified
PayloadSchema-valid
TrafficWithin limit
#sec-zero-trust · S8

8. Zero Trust Micro-Perimeters & Continuous Policy Engine

Model requests using identity, device posture, source zone, destination zone, MFA, and action under continuous verification.

Managed employee access zone

Sensitive data store

Retrieve permitted information

Trust signals

Evaluate the path to see whether policy will Allow, require Step-up MFA, or Deny the request.

Request path visualization

Static policy stages make the trust boundary explicit before any decision is applied.

Source zoneWorkforceRequest origin
Policy engineEvaluate signalsVerify every signal
Destination zoneDataProtected resource
Current pathworkforce → data · read

Every hop is evaluated with the same signals; being on a workforce or workload network does not grant implicit access.

03 · OperationsLabs S9–S11

Security Operations & Supply Chain

SOC alert triage, incident containment, SIEM detection rules, and CycloneDX/SPDX SBOM audits.

#sec-incident-response · S9

9. Incident Response Lifecycle & SOC Alert Triage

Practice a repeatable incident lifecycle against safe, synthetic alerts: signal classification, forensic preservation, and containment.

Credential stuffing burst

Identity gateway

A concentrated authentication failure pattern is targeting several customer accounts from rotating source addresses.

  • •78 failed sign-ins in 10 minutes
  • •12 accounts targeted
  • •No successful privileged login observed
Severity classification
0 assets10 assets
Incident lifecycle

Complete the controls, then score the response to see priority and the evaluator’s next action.

SOC handoff checklist

  • • Keep alert notes factual and timestamped.
  • • Preserve evidence before removing persistence.
  • • Escalate based on business impact, not signal volume alone.
#sec-siem · S10

10. SIEM Detection Rules & Log Analysis Lab

Query synthetic authentication, API, WAF, and cloud audit events with correlation rules.

Find events with five or more failed attempts.

Structured event stream

Synthetic events only; source addresses use documentation ranges.

8 of 8 events
Synthetic SIEM events filtered by source and severity
Event IDSourceSeverityKind / summaryUserFailedPrivilegeBytes out
auth-001authenticationhighlogin-failureRepeated sign-in failures for one accountalex8——
auth-002authenticationlowlogin-successSuccessful sign-in after one retrymorgan1——
api-014apilowtoken-refreshRoutine service token refreshservice-orders——0.0 MB
api-033apicriticalbulk-exportLarge response volume from customer export endpointjordan——1.85 MB
waf-009wafmediumblocked-requestBurst of rejected authentication-shaped requestsanonymous6——
waf-010waflowblocked-requestSingle malformed request blocked at edgeanonymous2——
cloud-021cloud-audithighrole-changeProduction role granted outside maintenance windowsam—Yes—
cloud-022cloud-auditlowpolicy-readRead-only policy inspectionauditor——0.0 MB

Choose a rule and optional filters, then run detection to see evaluator-matched event IDs and the analyst conclusion.

#sec-supply-chain · S11

11. Software Supply Chain & SBOM Policy Analyzer

Inspect a synthetic package inventory for vulnerability flags, immutable versions, fixture provenance, and license policy before release.

Package inventory

The evaluator re-checks every row whenever the license policy changes.

5 packages
Software bill of materials package inventory
PackageVersionSeverityFixture attestationLicense
express4.19.2highSignedMIT
lodash4.17.21mediumSignedApache-2.0
axios^1.7.2(unpinned)lowSignedMIT
internal-plugin2.1.0noneUnsignedApache-2.0
legacy-parser1.4.0noneSignedGPL-3.0
License allowlist

Only selected SPDX identifiers may ship in this local policy. Toggle a license to re-run the fixture evaluation.

Release policyBlock
BLOCK

6 findings require attention before release.

Evaluator findings

  • express has a high vulnerability.
  • lodash has a medium vulnerability.
  • axios has a low vulnerability.
  • axios is not pinned to an immutable version.
  • internal-plugin is not signed.
  • legacy-parser uses disallowed license GPL-3.0.

Allowlist currently contains 2 of 3 licenses seen in the inventory.

04 · PostureLabs S12–S14

Cloud Posture & Privacy Compliance

Kubernetes pod security admission, multi-control cloud compliance scoring, and data classification.

#sec-container-security · S12

12. Container Security & Admission Controller Lab

Model a strict Kubernetes admission policy: non-root users, read-only root filesystems, and dropped Linux capabilities.

Pod security controls

Enable each control that is enforced by your workload policy. Host access controls are secure when their toggles remain off.

Admission decisionRejected
DENY

6 controls failed and must be remediated.

Failed controls

  • Container must run as a non-root user.

    Remediation: Set a pod or image securityContext with runAsNonRoot: true and a non-zero runAsUser.

  • Container root filesystem must be read-only.

    Remediation: Set securityContext.readOnlyRootFilesystem: true and mount explicit writable volumes where needed.

  • Host networking is not permitted.

    Remediation: Remove hostNetwork: true and expose the service through a cluster Service or ingress.

  • Host path mounts are not permitted.

    Remediation: Remove hostPath volumes and use an approved persistent volume or projected secret instead.

  • Image signature verification is required.

    Remediation: Sign the image in CI and configure admission policy to verify its registry signature.

  • CPU and memory limits are required.

    Remediation: Declare CPU and memory requests and limits in the workload specification.

Controls passing1
Controls failed6
Policy modeStrict admission
#sec-cloud-posture · S13

13. Cloud Security Posture Management (CSPM) Scanner

Review a simulated AWS account snapshot across identity, storage, network, logging, and KMS controls.

Posture score

0

Grade F

Open findings

7

Evaluator-calculated risk

Resolved findings

0

Marked fixed locally

Last recalculation

Not run yet

AWS findings (7)

Select a finding to inspect evidence and remediation.

Cloud security posture findings
ControlFindingSeverityStatus
IAM

arn:aws:iam::000000000000:root

critical
S3

s3://acme-prod-invoices

high
VPC

vpc-0f42a1e9 / subnet-07b3c4d1

medium
CloudTrail

arn:aws:cloudtrail:us-east-1:000000000000:trail/example-audit

high
KMS

key/7e6d0d5c-4dcb-4ae5-9a19-prod-data

medium
Security groups

sg-0a8d66bd / prod-postgres

critical
IAM

user/example-deploy / EXAMPLE_KEY_ID

low
#sec-privacy-compliance · S14

14. Data Classification & Privacy Controls Lab

Classify example data assets, inspect mapped protection controls, and complete a privacy readiness checklist.

Example data inventory

Choose a field, then classify it according to its sensitivity and use.

Example fields and data classifications
FieldExample valueClassification

Link activity to a customer account

acct_7F29D1internal

Send account notifications

alex@example.testconfidential

Reference a vaulted payment method

tok_visa_••••4242restricted

Display a catalog item

Network Fundamentalspublic
Classify email_address

Privacy readiness checklist

Use the checklist to turn classification into operating controls.

0/5 complete